Weekly malware update – 2010/Jan/07

Weekly malware update. You can track all updates by following our malware_updates category.

*If your site has been affected with any of these issues, contact us at support@sucuri.net or visit http://sucuri.net to get help or if you want to share some information with us.

nit-news.com + a.lobose.strangled.net

Another command and control (C&C) for blackhat SEO Spam. The attackers added the following code on the hacked sites:

Which contacts nit-news.com/domains.txt to get the web site to be used in the spam. It only displays the SEO Spam if the attempt comes from the Google range of IP addresses. Right now, the domain being used is a.lobose.strangled.net, but changes almost daily.

oooabterast0.co.cc and friends

Many of the hacked sites we dealt with this week had a new iframe added to the site by the attackers, then loaded malware from oooabterast0.co.cc and other sites. All of them ended up on .co.cc and were hosted at 91.217.249.55.

social-stats.info

This one infected quite a few sites this week, despite being an old malware string (we saw quite a bit of this a few weeks ago). The affected sites had a site loaded via iframe or javascript, without any obfuscation.

Most of the affected sites got hacked through stolen FTP/SSH credentials. According to Google, more than 800 sites got hacked with it.

That’s it for this week. If you have questions, email us at support@sucuri.net or visit our site: http://sucuri.net

David Dede is a Security Researcher in the SucuriLabs group. He spends most of his time dissecting vulnerabilities and security issues. You won't find him on Twitter because he is paranoid about privacy.